Remote Code Execution Vulnerability in Atlassian Bitbucket Data Center
CVE-2022-26133
Key Information:
- Vendor
- Atlassian
- Status
- Vendor
- CVE Published:
- 20 April 2022
Badges
Summary
A security vulnerability exists in Atlassian Bitbucket Data Center, specifically in the SharedSecretClusterAuthenticator component. This flaw allows a remote, unauthenticated attacker to execute arbitrary code, potentially leading to significant security breaches. The vulnerability arises due to improper handling of Java deserialization, making systems running versions from 5.14.0 up to 7.20.0 susceptible if not properly patched. Users are urged to update their installations promptly to mitigate potential threats.
Affected Version(s)
Bitbucket Data Center 5.14.0
Bitbucket Data Center < 7.6.14
Bitbucket Data Center 7.7.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved